2V0-71.23 exam dumps

2V0-71.23 practice question 217 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 217

Select 2

You are a platform engineer managing a Tanzu Kubernetes Cluster (TKC) deployed on vSphere with Tanzu. The development team wants to integrate the cluster with their corporate identity provider (IdP) for authentication and enforce role-based access control (RBAC) for specific namespaces. Which of the following authentication and authorization methods can be used to achieve this?

  1. A

    Integrate the Tanzu Kubernetes Cluster with an external OIDC provider for user authentication.

  2. B

    Configure Kubernetes-native RBAC roles and bindings to enforce namespace-level access control.

  3. C

    Use kubeconfig files with static user credentials for all developers.

  4. D

    Leverage vSphere Single Sign-On (SSO) for cluster authentication without additional configurations.

  5. E

    Deploy a custom webhook for authentication and implement a custom RBAC solution.

Show answer and explanation

Correct answers: A, B

Explanation

To enable corporate identity provider integration and enforce namespace-level access control, OIDC providers can be used for user authentication, and Kubernetes-native RBAC can enforce permissions at the namespace level. Kubeconfig files with static credentials are insecure, vSphere SSO is not designed for this use case, and custom solutions are unnecessary when existing mechanisms meet the requirements.

  • A. Correct.

    Integrating with an external OIDC provider enables user authentication via a corporate IdP, which is a common approach for managing access to Tanzu Kubernetes Clusters.

  • B. Correct.

    Kubernetes-native RBAC is the recommended way to enforce fine-grained access control, such as namespace-level permissions, within a Tanzu Kubernetes Cluster.

  • C. Incorrect.

    Using kubeconfig files with static credentials is not secure or scalable for managing multiple users and is not recommended for production environments.

  • D. Incorrect.

    While vSphere SSO can be used to authenticate with the Supervisor Cluster, it is not directly applicable to Tanzu Kubernetes Clusters for integrating with a corporate IdP or managing RBAC.

  • E. Incorrect.

    Custom webhooks and custom RBAC solutions are not typically necessary or recommended when Kubernetes-native RBAC and OIDC integrations are available and sufficient for most use cases.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam